check_integration
Run live pass/fail checks on your app's Gemmein access boundaries after wiring and before go-live: validate anonymous access, public collection visibility, and user isolation.
Instructions
Call after wiring the app to Gemmein and before telling your human it is done — and again before go-live. Runs the reaffirm boundary checks live against the caller's own app; returns structured pass/fail (structuredContent: checks, notes, failedCount, passed). Tier A (public pk_ key only): the collection name is valid, anonymous reads and writes of a private collection are refused, an optional public collection reads as its rule intends — safe against any environment, live included. Tier B (add the sk_dev secret key): proves one user cannot read another's private records, using two throwaway test sessions in the DEV environment. sk_live is refused by design — never pass a live secret to any tool; dev and live enforce the same rules, so isolation proven in dev holds in live. The only writes anywhere are Tier B's own probe records in the caller's dev environment, deleted at the end of the check. A failed check means the app's assumptions drifted from its rules — fix before shipping.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| apiUrl | No | optional: API base URL override (local/dev API); omit for production Gemmein | |
| publicKey | Yes | the app's public pk_ key | |
| secretKey | No | optional: the sk_dev secret key — enables Tier B isolation proof (sk_live is refused) | |
| testUsers | No | optional: the two Tier-B test emails (default reaffirm-a/b@test.dev) | |
| timeoutMs | No | overall time budget, default 30000 | |
| publicCollection | No | optional: a community/public_read collection to confirm anonymous readability | |
| privateCollection | Yes | a collection with the `private` rule |